The I18n Project maintains a modestly represented internationalization library whose embedded presence across web applications and localization frameworks gives it broader relevance than its narrowly focused product line might suggest. Its observed vulnerability pattern centers on input-handling and encoding issues, including improper input validation and cross-site scripting weaknesses that arise from the parsing and rendering demands of multilingual content processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I18n Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7791HIGH This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/Localiz | Dec 11, 2020 | 7.5 | 24 | NO | NO |
CVE-2014-10077HIGH Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation whe | Nov 6, 2018 | 7.5 | 21 | NO | NO |
CVE-2013-4492MEDIUM Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::M | Dec 7, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I18n Project.
Media articles that mention a CVE ID that affects a product developed by I18n Project — matched by CVE ID, not by vendor name.